Jesse D'Aguanno's Avatar

Jesse D'Aguanno

@x30n

Hacker, Vuln Research, 2x winner DEF CON CTF, Founder & CEO Blackwing Intelligence, not a CISSP

148
Followers
138
Following
16
Posts
17.10.2023
Joined
Posts Following

Latest posts by Jesse D'Aguanno @x30n

Unfortunately, security properties address one piece of the overall goal, and are sometimes conflicting. So you have to first identify what _your_ goal is, in terms of security, and implement measures that apply to the properties that are important to that goal.

25.03.2025 19:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Us: Use MFA for security
Everyone: OK, secure!
Us: Well, only if you’re not being phished, and no one can subvert the delivery mechanism, and …
Everyone: πŸ™„

25.03.2025 19:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

We (security people) have done a really bad job communicating what security properties are (and aren’t).

Us: Use Signal for security
Everyone: OK, using Signal, now I’m **secure**!
Us: Well, only if the ends aren’t compromised, and you can trust the other parties, and …
Everyone: πŸ™„

25.03.2025 19:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Security isn’t binary. We need to somehow teach people to think in terms of simple threat models.

25.03.2025 19:44 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

+1

12.03.2025 12:30 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

So Soft, so ICEy

11.03.2025 18:44 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
RE//verse RE//verse is a premier reverse engineering, vulnerability research and malware analysis conference. We offer trainings and talks from industry-leading experts.

Really looking forward to the inaugural RE//verse conference this week! See y’all in Orlando!!
re-verse.io

25.02.2025 22:59 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I’m getting excited for RE//verse!

18.01.2025 04:07 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

We're pleased to announce Natalie Silvanovich @natashenka.bsky.social as the keynote speaker for the inaugural RE//verse. She might have started out hacking Tamagotchis, but she certainly didn't stop there!

18.01.2025 01:19 πŸ‘ 17 πŸ” 7 πŸ’¬ 1 πŸ“Œ 2

Wow, that’s high praise. Ordering

18.12.2024 03:47 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

num

12.12.2024 00:17 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Glad to see you’ve gotten on board the Binja train πŸš‚ πŸ˜‹

09.12.2024 18:23 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Oh, I never posted my gotofail story on here.

Early 2014, someone came to me about a catastrophic vulnerability in Apple's TLS implementation.

I shit you not, they'd overheard someone at a bar drunkenly bragging about how they were going to sell it to a FVEY intelligence agency for six figures.

17.11.2024 23:22 πŸ‘ 458 πŸ” 101 πŸ’¬ 7 πŸ“Œ 20
A Touch of Pwn - Part I Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations

Boom! πŸ’₯
Windows Hello fingerprint authentication bypassed on top three devices:
- Dell Inspiron
- Lenovo ThinkPad
- Microsoft Surface Pro
Still waiting for recordings from our BlueHat talk to drop, but here's our writeup: blackwinghq.com/blog/posts/a...
#infosec #security #vulnresearch

21.11.2023 19:49 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
A Touch of Pwn - Part I Blackwing Intelligence provides high-end security engineering, analysis, and research services for engineering focused organizations

Boom! πŸ’₯
Windows Hello fingerprint authentication bypassed on top three devices:
- Dell Inspiron
- Lenovo ThinkPad
- Microsoft Surface Pro
Still waiting for recordings from our BlueHat talk to drop, but here's our writeup: blackwinghq.com/blog/posts/a...
#infosec #security #vulnresearch

21.11.2023 19:49 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

There are some legacy security professionals that wear β€œI don’t code” as a badge of honor, but they’re dying out. Just like traditional system administration was replaced by devops.

05.11.2023 21:55 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

how to software, any day.

Although my background is in vulnerability research, this is not only applicable to finding vulns, appsec, etc. Security operations, network security, etc.Β  automation is the future (current in mature orgs).

…

05.11.2023 21:55 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Advice to juniors or those looking to get into #cybersecurity:
Learn to code

Software is at every level of the stack. Strong software engineering skills will serve you well throughout your career. I would rather teach a strong software engineer security over teaching a traditional security person …

05.11.2023 21:53 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

πŸ‘‹ blue sky

05.11.2023 21:48 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0